DNS Doctoring 296600

Is there any way of disabling the DNS doctoring of the Pix (v 6.3). We've
just put one in on our network and created a static NAT mapping for the mail
server. If we query any DNS server on the internet from within the network
it shows as the internal address and so for a while we thought that the DNS
had gone screwy! Now it seems apparent that the Pix is intercepting the DNS
replies and changing them to the internal address.

However, there is no DNS fixup and no alias command configured and so now I
can't work out how to disable this feature.

Any ideas anyone?

Chris.



0
Chris
12/19/2003 8:01:05 PM
comp.dcom.sys.cisco 25307 articles. 0 followers. Post Follow

2 Replies
672 Views

Similar Articles

[PageSpeed] 45

On Fri, 19 Dec 2003 14:01:05 -0600, Chris wrote:

> Is there any way of disabling the DNS doctoring of the Pix (v 6.3).
> We've just put one in on our network and created a static NAT mapping
> for the mail server. If we query any DNS server on the internet from
> within the network it shows as the internal address and so for a while
> we thought that the DNS had gone screwy! Now it seems apparent that the
> Pix is intercepting the DNS replies and changing them to the internal
> address.
> 
> However, there is no DNS fixup and no alias command configured and so
> now I can't work out how to disable this feature.
> 
> Any ideas anyone?
> 
> Chris.


6.3.1?  There was a bug in 6.3.1 -or- 6.3.2 that did this exact thing.
Upgrade to 6.3.3.

Rik Bain
0
Rik
12/19/2003 8:24:45 PM
"Rik Bain" <rik@remove.bainz.org> wrote in message
news:pan.2003.12.19.14.24.45.39641.7601@remove.bainz.org...
> On Fri, 19 Dec 2003 14:01:05 -0600, Chris wrote:
>
> > Is there any way of disabling the DNS doctoring of the Pix (v 6.3).
> > We've just put one in on our network and created a static NAT mapping
> > for the mail server. If we query any DNS server on the internet from
> > within the network it shows as the internal address and so for a while
> > we thought that the DNS had gone screwy! Now it seems apparent that the
> > Pix is intercepting the DNS replies and changing them to the internal
> > address.
> >
> > However, there is no DNS fixup and no alias command configured and so
> > now I can't work out how to disable this feature.
> >
> > Any ideas anyone?
> >
> > Chris.
>
>
> 6.3.1?  There was a bug in 6.3.1 -or- 6.3.2 that did this exact thing.
> Upgrade to 6.3.3.
>
> Rik Bain

Yup, 6.3(1). Thanks for that. I'll upgrade on Monday.

Much appreciated Rick.

Chris.



0
Chris
12/19/2003 8:54:27 PM
Reply:

Similar Artilces:

DNS Doctoring with a cisco router
hello. I'm wondering if there's a command that is similar to the PIX firewall's ALIAS command on a Cisco Router. Can anyone help me here? Thanks, Ben On Tue, 25 Nov 2003 16:32:22 -0600, Cool Guy Bri wrote: > hello. > > I'm wondering if there's a command that is similar to the PIX firewall's > ALIAS command on a Cisco Router. Can anyone help me here? > > Thanks, > Ben According to Document 26704, NAT Frequently Asked Question, it does DNS doctoring by default. Rik Bain Thank You for your help Rik! ben! Rik Bain <rik@remove.bainz.or...

Cisco!! Cisco!! Cisco!!
From http://groups.google.com/group/comp.dcom.sys.cisco/about Top posters This month 18 mer...@geeks.org 11 alagmy 10 bo...@hotmail.co.uk 9 galt...@hotmail.com 9 nom...@example.com 8 troffa...@hotmail.com 8 igor.mamuzicmakni_...@zg.t-com.hr 7 pfisterf...@gmail.com 7 darfun....@gmail.com 6 jfmezei.spam...@vaxination.ca All time 4799 rober...@ibd.nrc-cnrc.gc.ca 2930 aaron@cisco.com 2813 Merv 2370 t...@cisco.com 2356 vcjo...@networkingunlimited.com 1984 b...@cisco.com 1959 bar...@genuity.net 1898 hb...@_nyc.rr.com.remove_ 1745 u...@alp.ee.pbz 1670 bar...@bbnplanet.com -- ...

Doctor, Doctor...
Given there has uncharacteristically been no post here from Doc Dwarf for nearly 4 weeks, and he is (also uncharacteristically) not responding to private mail, there seems to be some reason for concern. He did mention some health problems a little while ago. Doc, if you are seeing this, please know you are missed here and (if it is appropriate) every wish for a speedy recovery. Pete. -- "I used to write COBOL...now I can do anything." On 8/24/2011 6:42 PM, Pete Dashwood wrote: > Given there has uncharacteristically been no post here from Doc Dwarf for > nearly 4 wee...

DNS doctoring.
Hi all, we have a web server inside our LAN. We have PIX32 between the world and us. I know that traffic can not come from one interface and flow to the same interface (in this case the inside one) This mean that internal clients can not access web server (e.g. www.pincopallo.it) because the DNS response return an external IP but the real machine (192.168.31.26) is inside the lan. We have just insert the static and conduit statement for internet people to access our web server. static (inside,outside) IP_of_www.pincopallo.it 192.168.31.26 netmask 255.255.255.255 0 0 conduit permit tcp host ...

DNS and cisco routers
Hi gents, my domain machines don't work correctly with my dns, but they do with my dhcp , so I wonder if there is any parameter such as ip helper-address for dhcp, that should be configured to make dns work in different connected networks. Thanks in advance . In article <1170349835.141916.232400@k78g2000cwa.googlegroups.com>, "Sako" <lluis.clemente@gmail.com> writes: > Hi gents, my domain machines don't work correctly with my dns, but > they do with my dhcp , so I wonder if there is any parameter such as > ip helper-address for dhcp, that should be con...

DNS Relay on Cisco?
Hi, I tried to use a cisco router as a dns relay for my LAN, but without success. I've set # ppp ipcp dns request to learn the name server from the ppp session, and a # ping www.google.de succeeds. I read about a "ip dns server" command, but the IP ADSL PLUS IOSse I've tried (c1700-sy7-mz.124-3b.bin, c1700-sy7-mz.123-7.XR6.bin) don't accept this command in conf t. It's a Cisco 1721. Any hints? Thanks in advance, Jens ...

DNS Doctoring with PIX
I have upgraded to PIX 6.3(4) and I am trying to use the DNS command in my STATIC to access my inside server via domain name. I do not use an internal DNS server. My question is, am I missing some other command, sysopt or fixup to make this work? The static I have does work for outside-inside traffic, but still does not 'doctor' the DNS inquiries for inside use. I do have the fixup protocol dns maximum-length 512 statement. There really isn't a lot of info on using this command in a static. I know there is an alias command, but I only have one IP address that I need to...

DNS on Cisco RAS
I configured Cisco 3600 to work as RAS & I added the : ip name-server x.x.x.x ip name-server y.y.y.y for the DNSs to be used by dialup clients. but I noticed that when the client dial-in, they get wrong IPs for the DNS : 192.168.1.1 which are not the correct IPs of our DNSs. On Thu, 20 Nov 2003 16:31:02 -0600, hakim soso wrote: > I configured Cisco 3600 to work as RAS & I added the : ip name-server > x.x.x.x > ip name-server y.y.y.y > for the DNSs to be used by dialup clients. but I noticed that when the > client dial-in, they get wrong IPs for the DNS : 192.168.1.1 wh...

DNS doctoring, alias .
Does the DNS doctoring work without specifing protocols and ports or does it with them as well? Are internal DNSes needed for the doctoring to work properly or is it the same thing to have clients with external DNSes specified and answers from them are anyway translated? Alex. "AM" <am@am.am> wrote in message news:8jxZd.14401$zZ1.354966@twister1.libero.it... > Does the DNS doctoring work without specifing protocols and ports or does it with them as well? yes, you can use the alias command completly "stand-alone" look at the Cisco doc for "understanding th...

DNS doctoring 300001
Hi, I have problem with DNS doctoring in PIX 6.3(3) I set alias command and sysopt noproxyarp inside and it doesn't work. Out customer has linux with masquarade and he has static and for outside DNS they see this domain as static IP and they can't achieve this server. Then I try set alias command. Any known bug or sth else ? Regards, grzybek ...

DNS Doctoring conversion?
Currently, we are using the ALIAS command for DNS doctoring to access private IP resources inside the network that are also accessed from outside the network: alias (inside) 10.y.y.249 209.x.x.35 255.255.255.255 I know that Cisco has said that they are only maintaining this command for backward compatability and recommend going to the STATIC entry. But, I am confused by this entry on how to properly implement. Any insight would help on the proper structure to continue being able to provide DNS doctoring access from the inside of the network. I am running a PIX 515 6.3(3) On Mon, 10 Nov 2...

cisco 2500 forward to dns
Hello Everyone, I have a cisco 2500 router that i am trying to add to my network. I've connected the cisco router to my linksys router (which is my main router) and I am able to telnet to the cisco router, configure etc...I am not able to get DNS working on the cisco router. I can ping all of the other computers and the linksys router from the cisco router. I've tried adding my isp name servers to the cisco router, but that's not working. I tried adding my linksys router as a name server on my cisco router and i am able to ping from the cisco router and i see the translation happe...

DNS Record in CISCO Router
I want to configure DNS Record in CISCO Router. I am using Router as internet server with DNS. If i configure it there users can connect to my configured sites locally. Hi, Could you be more specific? You need to let internet users access your web-servers. Am I correct? Giorgos -- NetPros Community Connecting IT Pros from all over the World http://netpros.freeforums.org On 11 =CD=EF=DD, 10:32, Ts8060 <ts.8...@gmail.com> wrote: > I want to configure DNS Record in CISCO Router. > I am using Router as internet server with DNS. > If i configure it there u...

Cisco 1700 and DNS cache
Is it possible to set Cisco 1721 with IOS IP Plus to catch all DNS queries. I mean that Cisco would be asking it't primary DNS first time client is asking router, but second time and next, only router response to that DNS query. How to do it? ...

Verifying DNS with Cisco 837
Hi All. I have a Cisco 837 Router and have configured it to obtain DNS from the ISP via the "ppp ipcp dns request" command on my Dialer interface. I am able to resolve addresses without problems, but would like to verify what dns servers were assigned to me. Does anyone know the "show" command or eqivalent that displays this? ...

Cisco or not Cisco for IDS
Hi, I need your point of view on this. I have to setup a IDS network and I do not know how to start my investigations on it. Well, it seems that Cisco has IDS appliances but everybody around me says that I also have to have a look at ISS Proventia ( www.iss.net/proventia ). Is the Cisco Management Application for IDS as easy as Site_Protector? How are the signature updates provided, by Cisco itself or through the CERT? If the bandwidth I have to monitor is about 200Mbits, what would be your choice is the Cisco catalogue? In the ISS catalogue? Many thanks, Alabama Alabama Circus wrote: &...

What are files Z80.SYS, Z80CCP.SYS and PRMTVPVT.SYS for?
Had a good Christmas this weekend? I came across diskettes with "Mailmerge 3.0 and Calcstar version 1.45 for CP/M 8080", that seem to be for a Dec Rainbow machine. Besides a Mailmerge overlay and the Calcstar files, some CP/M and some CP/M-86 files, there are three files on the diskettes that I never have heard of before: Z80.SYS, Z80CCP.SYS and PRMTVPVT.SYS. There are no ASCII texts in PRMTVPVT.SYS. The only ASCII text in Z80.SYS (at the end of the file) is "EI SPHLDI XCHGPCHLXTHLRET HLT CMC STC CMA DAA RAR RAL RRC RLC NOP CPI ORI XRI ANI SBI IN SUI OUT ACI ADI CALLJMP LDA...

Cisco 877
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Hi all, I have DHCP and DNS configured on my Cisco 877 and have been trying to get Dynmaic DNS updates running. Is this possible on an 877? If it is can someone please point me to some documentation I can read? Regards, - -- Russell Wood <http://www.dynode.net/~rjw/> -----BEGIN PGP SIGNATURE----- Version: GnuPG v2.0.11 (FreeBSD) iEYEARECAAYFAknPY+EACgkQRn6cGjGf/rs5CwCfXat58ivgcyjpw4VD7bOC9Uno EDcAnRuFu2bKTD4CPaUXMeXCcUi3PDbo =DW2N -----END PGP SIGNATURE----- > Hi all, > > I have DHCP and DNS configured on my Cisco 877 and h...

Turn a Cisco Router into a DNS server
Does anybody know how to make a Cisco Router act as a DNS server? Let me clarify that I'm not talking about relaying/forwarding DNS requests, from the router to another system that resolves DNS. I want the router to listen on port 53 for DNS queries; once the query is received the router should look to its own host table (Both perm and cached entries) and then return a name resolution (IP address) to the querying host. "jsh3323" <james.s.harris@certegy.com> wrote in message news:1143154686.536965.189000@t31g2000cwb.googlegroups.com... > Does anybody know how to make ...

Cisco VPN client intercepts DNS
I'm running the Cisco client on my Fedora Core 2 gateway to connect to a peer site's Windows servers. However, I want to continue to use the BIND DNS server on the gateway to connect to the Internet. When the VPN is up, my DNS packets seem to get intercepted and replies come from the peer's DNS server instead of the outside authoritative servers that were queried. What can I do to get the client to leave my DNS alone? Is this a setting in my peer's VPN server that needs adjusting? What would I need to ask for? (I don't need the DNS to resolve the peer's servers. ...

Cisco 801 (ISDN): DNS Relay
I've already written about my router and the ICMP problem, but I have one other query: On my old router, it acted as a sort of DNS relay. I added the internal ip address of the router under the DNS server setting on the clients, and the router relayed the requests to the name-servers given by the ISP. I can add 'ip nameserver xxx.xxx.xxx.xxx' to the router, but this doesn't seem to do the same thing. The router can resolve names, but it won't resolve names for my clients (If you understand what I mean!). As a result, I've had to add the namservers of the ISP to the...

DNS resolution fails on Cisco 2821
I have a cisco 2821 Intergrated Router. I have set the DNS address to our typical DNS and when I ssh into the cisco box I get DNS resolution but from any machine or network plugged into the cisco 2821 it fails. Here is my config as it is right now. _________________________________________________________________- Using 9028 out of 245752 bytes ! version 12.4 no service pad service tcp-keepalives-in service tcp-keepalives-out service timestamps debug datetime msec localtime show-timezone service timestamps log datetime msec localtime show-timezone service password-encryption service sequence-...

PIX DNS doctoring with 2003 server
A quick question guys. I recently put a few firewalls in a customer premises with a static NAT policy. Internally the clients were 192.168.1.x but extrenally they were 135.1.1.x statically mapped one for one. DNS always worked ok since there were no servers on these sites - I accepted the limitaion that the machines cannot ping by machine name. This worked loads of times. I then had another site exactly like this but had a server as well as just client PC's. The clients could not get their drive mappings on this server until I clicked the DNS option against the static transatio...

Dns doctoring/dnsmasq -V on bind?
Hi, After googeling a lot I kinda gave up and ended here. Im running a bind server, where we have out .loc zone on and also use it for caching. We have our domains hosted @ our ISP's DNS-Servers. Now recently management decided to migrate from cisco to linux-routers/firewalls. Now as you might know, there is a dns-doctoring feature on cisco devices, that will rewrite ip addresses in dns-query-responses. I found a nice non-cisco explanation by someone who had my problem some years ago: > My dns server sits outside my firewall on the internet and answers queries for bo...

Web resources about - DNS Doctoring 296600 - comp.dcom.sys.cisco

Hanson makes 'no apologies' for handling of data doctoring affair
Hanson makes 'no apologies' for handling of data doctoring affair

Queensland government accused of doctoring job loss figures
Close to 5000 health workers have lost their jobs since the LNP won office in 2012, almost 1900 more than the state government admits, Queensland ...

Pulitzer-winning photographer Narciso Conteras fired by AP after doctoring Syria photo
... from a photo of the Syria conflict. A Pulitzer Prize-winning photographer has been sacked by the Associated Press (AP) news agency after doctoring ...

Congressman doubles down, accuses NOAA scientists of doctoring results
Rep. Lamar Smith claims temperature data were fudged for Obama Administration.

Doctoring The Transcript
It was bad enough when Rush Limbaugh smeared American troops who question the president as “phony soldiers.” Next, backtracking, Rush insisted ...


Internal Medicine Residents receive ultimate symbol of doctoring — white coat
Twelve internal medicine residents on Tuesday entered into the world of medicine when each received the ultimate symbol of doctoring — the coveted ...

Warning To Democratic Candidates: The GOP Is Doctoring Your Wikipedia Pages
... care that they look like fools? Much of what they do isn't all that apparent. They're a sneaky, shady bunch and BuzzFeed caught them doctoring ...

Clay Buchholz Accused Of Doctoring Baseball By Sportsnet’s Dirk Hayhurst In Toronto
A former MLB pitcher claims Clay Buchholz had the aid of a foreign substance on the mound on Wednesday night. Boston News, Sports, Weather, Traffic ...

TGI Fridays nailed for doctoring booze
"Operation Swill" reveals that TGI Fridays and other restaurants poured cheap alcohol or worse into premium bottles

Resources last updated: 2/18/2016 4:05:28 PM